CVE-2020-25010: Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Firmware
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request parameters as an instruction to write a file.
Affected products
- Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Firmware: version r0002.p05 only
Published 2020-12-17. Last modified 2026-06-17.